Compliance reference
The whole module at a glance — and straight answers to the questions that only come up at the worst moment.
Roles and permissions
| Who | Can |
|---|---|
| Compliance Manager (built-in role) | Run checks, resolve issues, and export reports — without full admin rights. |
| People without the permission | Rules, reports, and standards are hidden, not merely greyed out. |
| AI agents | Can be granted narrow access — view status, run checks, resolve issues, set origin or licences — and can never reach anything the person they work for cannot. Verifying an AI disclosure is human-only. |
| Any plan | Recording origin works everywhere; the checks, issues, and reports open up when your plan includes compliance. |
Severities, states, standards
| Thing | Values |
|---|---|
| Severity | Information → … → Blocking. Only an open blocking issue stops a campaign post from publishing; other severities inform. |
| Issue queues | Needs review · Open · Snoozed · Resolved · Dismissed — plus Returned, for an issue that comes back after resolution. |
| Standards | Brand guidelines · EU AI Act · WCAG 2.2 AA · GDPR — all four on from day one, each scored separately, switchable off and back. |
| Check types | Fifteen, from required metadata and naming through text-in-image, image subjects, palette, accessibility, licences, and AI disclosure. |
Limits and windows
| Thing | Value |
|---|---|
| Brand checks running at once | Up to three manually started checks; a check that stalls ages out after two hours. Upload-triggered checks don't count against the cap. |
| Check size | Very large brand checks run in the background; beyond fifty thousand assets a single check is refused. |
| Snooze | Up to a year ahead, never in the past |
| Returned issues | An issue resolved within the last 90 days that reappears is marked Returned; after 90 days it reopens as new — with its occurrence history still accumulating. |
| Audit reports | Downloadable for 30 days after they're ready; then regenerate. Each download link lasts about a minute. |
| AI activity tab | Last 7, 30, or 90 days; the newest 100 entries per window |
Notifications
| Moment | Who hears |
|---|---|
| An issue is assigned to you | You |
| A licence is about to expire, or has expired | The people who manage or assign licences — one warning, using the notice period your rules set at the time the licence was saved |
| An audit report is ready | Whoever requested it |
| A check finds new issues | Nobody, today — new and returned issues land in the queues and on the Hub, but don't ring a bell |
What happens when… people come and go
| When… | What happens |
|---|---|
| A teammate deletes their account | Every compliance action they took survives — rules, locks, resolutions, reports. The activity log shows them as “a team member”; a lock panel simply omits who locked it. |
| The person who locked a file has left | Nothing is locked forever: anyone with the lock permission can release it, with a written reason that's kept on the record. Locks have no expiry. |
| The person who set up an AI agent has left | The agent keeps its own seat and key and keeps working on its own authority until an admin pauses or removes it. Only actions on behalf of the departed person are refused. |
| You try to assign an issue to a deactivated member | The picker offers active members only. |
What happens when… time passes
| When… | What happens |
|---|---|
| A snoozed issue's date passes | It reads as acknowledged again, but stays in the Snoozed tab rather than jumping back into Open — look for it there. |
| A licence expires on a publicly shared asset | Public pages and downloads leave it out from that moment; inside the brand, downloading warns with the details (or is blocked, if a rule says so). |
| Your subscription lapses | Nothing is deleted and everything stays readable; running checks, resolving issues, and generating reports pause until the subscription is active again. |
| You want a recurring scheduled check | Not today — checks run on every upload and whenever you ask; a periodic brand check is something you run. |
| The brand score doesn't move after uploads were checked | By design: only a brand-wide check you run records a score, so one slice can never overwrite the brand's number. A check that evaluated nothing records no score rather than a misleading 100. |
What happens when… files and reports are involved
| When… | What happens |
|---|---|
| A file with an open issue is trashed or deleted | The issue stays in its queue — nothing auto-resolves — and the issue page says the file is no longer available. |
| You pick a reporting period for an audit report | The period is printed on the report; the issues and score it contains are the current state at generation, filtered by standard — and the report says so if a newer check left the score untouched. |
| A caption is missing in one of your languages | It depends on the rule: if the rule names languages, an unpublished language is exempt; if it names none, every language must meet the minimum. |
| An AI agent edits a file with no origin recorded | It's stamped AI-assisted automatically, on the first write only — a person's entry always wins over the stamp. |
| An AI assistant wants to check a file before publishing | It can, with the asset-check access and view rights on the file, when your plan includes compliance — advisory only, nothing is saved. |
Cross-pillar truths
| Thing | How it works |
|---|---|
| Campaign publishing | The publish pre-flight re-runs at fire time and blocks on an open blocking issue, naming it and linking to it. |
| Review approval | Has no compliance check — approving a review never consults compliance, and review activity never triggers a scan. |
| The Brand Hub | Raises missing AI disclosures and licences expiring soon as things to act on. |
| The activity log and your activity page | Narrate compliance work in plain sentences; a whole check run collapses into one line when it flags more than one issue. |